I want to install the universal forwarder on a domain controller in domain 2 with trust to another domain 1.
Do I need to use the domain account or just local account to forward the security logs to the Splunk server that is in domain 1?